Lateral Movement Visualization for Network Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting and containing lateral network intrusions are overly manual and slow, making it difficult to quickly identify and remediate threats within the limited 'breakout time' before attackers can access critical data and resources.
Innovation Solution
An automated system for visualizing and remediating lateral movements in computer networks, which includes the collection and filtering of event logs, visual mapping of connections, and the ability to identify the initial infection vector and scale of intrusion, using a security computer machine with a processor and secure memory to render graphical images of network connections and provide contextual data for quick analysis and remediation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If manual methods are used to detect and contain lateral network intrusions, then detection accuracy can be maintained, but the response time becomes too slow to effectively remediate threats within breakout time
Solution Approach 1:
The system performs preliminary actions by continuously collecting and analyzing network traffic data before intrusions fully establish themselves. Security rules are pre-configured to automatically detect lateral movement patterns, enabling the system to identify and respond to threats during the reconnaissance and credential gathering phases, rather than waiting for manual detection after full compromise.
Solution Approach 2:
The patent replaces manual mechanical analysis with automated electronic systems. Machine learning models and automated correlation engines substitute for human analysts examining logs and network traffic. This substitution enables real-time processing of vast amounts of data at speeds impossible for manual methods, directly addressing the speed-response time contradiction.
2Reliability
If comprehensive network monitoring is implemented to detect all lateral movement activities, then detection coverage is improved, but system complexity and resource consumption increase significantly
Solution Approach 1:
The system applies local quality by implementing detection rules tailored to specific network segments, host types, and threat scenarios. Rather than uniform monitoring across the entire network, security policies are customized for different zones and asset classes. This targeted approach maintains high detection coverage for critical areas while reducing overall system complexity and resource requirements.
Solution Approach 2:
The monitoring system is segmented into modular components that can be independently deployed and configured. Detection rules are divided into discrete security policies that can be selectively enabled based on network needs. This segmentation allows the organization to implement comprehensive monitoring where required while maintaining simpler configurations elsewhere, balancing coverage with complexity management.
3Measurement precision
If detailed analysis of all network connections is performed to identify intrusion paths, then detection precision is improved, but the time required for analysis exceeds the limited breakout time available
Solution Approach 1:
The system applies partial action by focusing analysis on the most critical connection attributes and high-risk traffic patterns rather than examining every detail of all network communications. Automated correlation of key indicators enables precise intrusion path identification with sufficient speed to contain threats within breakout time, accepting that not every connection detail will be fully analyzed.
Solution Approach 2:
The system implements feedback loops where initial detection results immediately trigger automated response actions and refined analysis. As the system detects potential lateral movement, it dynamically adjusts monitoring focus to the affected network segments, concentrating analytical resources on the most relevant data. This feedback-driven approach achieves high precision without requiring exhaustive analysis of the entire network.
Data Source
AI summary
Aspects of the disclosure relate to visualization of lateral movements of an intruder on a network by connecting to computers and/or resources under investigation. A first computer is identified for investigation. Logs regarding incoming and outgoing connections to the computer are extracted and can be prefiltered based on specific IDs or other criteria. Maps of incoming and outgoing connections are stored in memory along with event information. Each subsequent computer to which the computer connected or resource accessed is identified. The map is updated based on logs from that computer or resource. A graphical image showing each applicable host, its connections, the chronology, and/or contextual information is generated and displayed. Individual hosts and other displayed data can be user-selectable to drill down and/or provide additional information. The process can repeat until all hosts, from patient zero to all endpoints, have been identified and rendered.


